Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

2026-04-08

CVE-2026-39534: WP Directory Kit <= 1.5.0 – Missing Authorization (wpdirectorykit)

The WP Directory Kit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-04-08

CVE-2026-39502: Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.38 – Unauthenticated SQL Injection (form-maker)

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.15.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to…
2026-04-08

CVE-2026-0814: Advanced CF7 DB <= 2.0.9 – Missing Authorization to Authenticated (Subscriber+) Form Submissions Excel Export (advanced-cf7-db)

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export form submissions to excel file.
2026-04-08

CVE-2026-39480: BackupBliss – Backup & Migration with Free Cloud Storage <= 2.1.1 – Unauthenticated Information Exposure (backup-backup)

The BackupBliss – Backup & Migration with Free Cloud Storage plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
2026-04-08

CVE-2026-39524: Masteriyo LMS – Online Course Builder for eLearning, LMS & Education <= 2.1.5 – Missing Authorization (learning-management-system)

The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-04-08

CVE-2026-0811: Advanced CF7 DB <= 2.0.9 – Cross-Site Request Forgery to Form Entry Deletion (advanced-cf7-db)

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes it possible for unauthenticated attackers to delete form entry via a forged request granted they can trick…
2026-04-08

CVE-2026-2942: ProSolution WP Client <= 1.9.9 – Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess (prosolution-wp-client)

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
2026-04-08

CVE-2026-39523: Solene Core <= 2.3.2 – Unauthenticated Local File Inclusion (solene-core)

The Solene Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive…
2026-04-08

CVE-2026-39470: Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails < 2.1.0 – Authenticated (Shop Manager+) Privilege Escalation (woo-cart-abandonment-recovery)

The Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.1.0 (exclusive). This makes it possible for authenticated attackers, with Shop Manager-level access and above, to escalate their privileges to that of an administrator.
2026-04-08

CVE-2026-3574: Experto Dashboard for WooCommerce <= 1.0.4 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'Navigation Font Size' Setting (experto-custom-dashboard)

The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Size', 'Navigation Font Weight', 'Heading Font Size', 'Heading Font Weight', 'Text Font Size', and 'Text Font Weight') in all versions up to and including 1.0.4. This is due to insufficient input sanitization (no…

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works